CVE-2023-54109
published 2025-12-24CVE-2023-54109: In the Linux kernel, the following vulnerability has been resolved: media: rcar_fdp1: Fix refcount leak in probe and remove function rcar_fcp_get() take…
PriorityP421medium5.3
EPSS
0.19%
9.0th percentile
In the Linux kernel, the following vulnerability has been resolved:
media: rcar_fdp1: Fix refcount leak in probe and remove function
rcar_fcp_get() take reference, which should be balanced with
rcar_fcp_put(). Add missing rcar_fcp_put() in fdp1_remove and
the error paths of fdp1_probe() to fix this.
[hverkuil: resolve merge conflict, remove() is now void]
Affected
21 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | linux | < linux 6.1.37-1 (bookworm) | linux 6.1.37-1 (bookworm) |
| linux | linux | — | — |
| linux | linux | >= 4710b752e029f3f82dd4a84d9dc61fe72c97bf82 < 418a8f3140e07f33bbd5a81625d0ef46c0732cef | 418a8f3140e07f33bbd5a81625d0ef46c0732cef |
| linux | linux | >= 4710b752e029f3f82dd4a84d9dc61fe72c97bf82 < 9df630dafa1a59946d1da6f070d4cb64f14ea57c | 9df630dafa1a59946d1da6f070d4cb64f14ea57c |
| linux | linux | >= 4710b752e029f3f82dd4a84d9dc61fe72c97bf82 < 1acb982e3616e70128994fdecf2368a259c8a489 | 1acb982e3616e70128994fdecf2368a259c8a489 |
| linux | linux | >= 4710b752e029f3f82dd4a84d9dc61fe72c97bf82 < 2322b262d2205720518785c2706a3283725ba402 | 2322b262d2205720518785c2706a3283725ba402 |
| linux | linux | >= 4710b752e029f3f82dd4a84d9dc61fe72c97bf82 < 45b7461d914c867ef21c74798da8c42d13d3a0df | 45b7461d914c867ef21c74798da8c42d13d3a0df |
| linux | linux | >= 4710b752e029f3f82dd4a84d9dc61fe72c97bf82 < 59c6addfaaaa09ff7654e4d8793cb16fd22a46d4 | 59c6addfaaaa09ff7654e4d8793cb16fd22a46d4 |
| linux | linux | >= 4710b752e029f3f82dd4a84d9dc61fe72c97bf82 < 48765ca7c6b71bf73a4cc8475a4bad9e2633cf61 | 48765ca7c6b71bf73a4cc8475a4bad9e2633cf61 |
| linux | linux | >= 4710b752e029f3f82dd4a84d9dc61fe72c97bf82 < c766c90faf93897b77c9c5daa603cffab85ba907 | c766c90faf93897b77c9c5daa603cffab85ba907 |
| linux | linux_kernel | >= 0 < 5.10.191-1 | 5.10.191-1 |
| linux | linux_kernel | >= 0 < 6.1.37-1 | 6.1.37-1 |
| linux | linux_kernel | >= 0 < 6.3.7-1 | 6.3.7-1 |
| linux | linux_kernel | >= 0 < 6.3.7-1 | 6.3.7-1 |
| linux | linux_kernel | >= 4.10.0 < 4.19.283 | 4.19.283 |
| linux | linux_kernel | >= 4.20.0 < 5.4.243 | 5.4.243 |
| linux | linux_kernel | >= 5.11.0 < 5.15.111 | 5.15.111 |
| linux | linux_kernel | >= 5.16.0 < 6.1.28 | 6.1.28 |
| linux | linux_kernel | >= 5.5.0 < 5.10.180 | 5.10.180 |
| linux | linux_kernel | >= 6.2.0 < 6.2.15 | 6.2.15 |
| linux | linux_kernel | >= 6.3.0 < 6.3.2 | 6.3.2 |
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
OSV
CVE-2023-54109: In the Linux kernel, the following vulnerability has been resolved: media: rcar_fdp1: Fix refcount leak in probe and remove function rcar_fcp_get() ta
osv·2025-12-24
CVE-2023-54109 CVE-2023-54109: In the Linux kernel, the following vulnerability has been resolved: media: rcar_fdp1: Fix refcount leak in probe and remove function rcar_fcp_get() ta
In the Linux kernel, the following vulnerability has been resolved: media: rcar_fdp1: Fix refcount leak in probe and remove function rcar_fcp_get() take reference, which should be balanced with rcar_fcp_put(). Add missing rcar_fcp_put() in fdp1_remove and the error paths of fdp1_probe() to fix this. [hverkuil: resolve merge conflict, remove() is now void]
GHSA
GHSA-mgj8-vp8h-hv58: In the Linux kernel, the following vulnerability has been resolved:
media: rcar_fdp1: Fix refcount leak in probe and remove function
rcar_fcp_get()
ghsa_unreviewed·2025-12-24
CVE-2023-54109 GHSA-mgj8-vp8h-hv58: In the Linux kernel, the following vulnerability has been resolved:
media: rcar_fdp1: Fix refcount leak in probe and remove function
rcar_fcp_get()
In the Linux kernel, the following vulnerability has been resolved:
media: rcar_fdp1: Fix refcount leak in probe and remove function
rcar_fcp_get() take reference, which should be balanced with
rcar_fcp_put(). Add missing rcar_fcp_put() in fdp1_remove and
the error paths of fdp1_probe() to fix this.
[hverkuil: resolve merge conflict, remove() is now void]
OSV
media: rcar_fdp1: Fix refcount leak in probe and remove function
osv·2025-12-24
CVE-2023-54109 media: rcar_fdp1: Fix refcount leak in probe and remove function
media: rcar_fdp1: Fix refcount leak in probe and remove function
In the Linux kernel, the following vulnerability has been resolved:
media: rcar_fdp1: Fix refcount leak in probe and remove function
rcar_fcp_get() take reference, which should be balanced with
rcar_fcp_put(). Add missing rcar_fcp_put() in fdp1_remove and
the error paths of fdp1_probe() to fix this.
[hverkuil: resolve merge conflict, remove() is now void]
Red Hat
kernel: media: rcar_fdp1: Fix refcount leak in probe and remove function
vendor_redhat·2025-12-24
CVE-2023-54109 kernel: media: rcar_fdp1: Fix refcount leak in probe and remove function
kernel: media: rcar_fdp1: Fix refcount leak in probe and remove function
In the Linux kernel, the following vulnerability has been resolved:
media: rcar_fdp1: Fix refcount leak in probe and remove function
rcar_fcp_get() take reference, which should be balanced with
rcar_fcp_put(). Add missing rcar_fcp_put() in fdp1_remove and
the error paths of fdp1_probe() to fix this.
[hverkuil: resolve merge conflict, remove() is now void]
Package: kernel (Red Hat Enterprise Linux 10) - Not affected
Package: kernel (Red Hat Enterprise Linux 6) - Not affected
Package: kernel (Red Hat Enterprise Linux 7) - Not affected
Package: kernel-rt (Red Hat Enterprise Linux 7) - Not affected
Package: kernel (Red Hat Enterprise Linux 8) - Not affected
Package: kernel-rt (Red Hat Enterprise Linux 8) - Not affe
Debian
CVE-2023-54109: linux - In the Linux kernel, the following vulnerability has been resolved: media: rcar...
vendor_debian·2023
CVE-2023-54109 CVE-2023-54109: linux - In the Linux kernel, the following vulnerability has been resolved: media: rcar...
In the Linux kernel, the following vulnerability has been resolved: media: rcar_fdp1: Fix refcount leak in probe and remove function rcar_fcp_get() take reference, which should be balanced with rcar_fcp_put(). Add missing rcar_fcp_put() in fdp1_remove and the error paths of fdp1_probe() to fix this. [hverkuil: resolve merge conflict, remove() is now void]
Scope: local
bookworm: resolved (fixed in 6.1.37-1)
bullseye: resolved (fixed in 5.10.191-1)
forky: resolved (fixed in 6.3.7-1)
sid: resolved (fixed in 6.3.7-1)
trixie: resolved (fixed in 6.3.7-1)
No detection rules found.
No public exploits indexed.
Wiz
CVE-2023-54109 Impact, Exploitability, and Mitigation Steps | Wiz
blogs_wiz·CVSS 5.3
CVE-2023-54109 [MEDIUM] CVE-2023-54109 Impact, Exploitability, and Mitigation Steps | Wiz
## CVE-2023-54109 :
Linux Debian vulnerability analysis and mitigation
In the Linux kernel, the following vulnerability has been resolved:
media: rcar_fdp1: Fix refcount leak in probe and remove function
rcar_fcp_get() take reference, which should be balanced with
rcar_fcp_put(). Add missing rcar_fcp_put() in fdp1_remove and
the error paths of fdp1_probe() to fix this.
[hverkuil: resolve merge conflict, remove() is now void]
Source : NVD
Published December 24, 2025
CNA Score N/A
Affected Technologies
Linux Debian
Linux Ubuntu
Has Public Exploit No
Has CISA KEV Exploit No
CISA KEV Release Date N/A
CISA KEV Due Date N/A
Exploitation Probability Percentile (EPSS) 10.8
Exploitation Probability (EPSS) N/A
Affected packages and libraries
linux-iot
linux-xilinx-zynqmp
Sources
Bugzilla
CVE-2023-54109 kernel: media: rcar_fdp1: Fix refcount leak in probe and remove function
bugzilla·2025-12-24
CVE-2023-54109 CVE-2023-54109 kernel: media: rcar_fdp1: Fix refcount leak in probe and remove function
CVE-2023-54109 kernel: media: rcar_fdp1: Fix refcount leak in probe and remove function
In the Linux kernel, the following vulnerability has been resolved:
media: rcar_fdp1: Fix refcount leak in probe and remove function
rcar_fcp_get() take reference, which should be balanced with
rcar_fcp_put(). Add missing rcar_fcp_put() in fdp1_remove and
the error paths of fdp1_probe() to fix this.
[hverkuil: resolve merge conflict, remove() is now void]
Discussion:
Upstream advisory:
https://lore.kernel.org/linux-cve-announce/2025122412-CVE-2023-54109-714c@gregkh/T
https://git.kernel.org/stable/c/1acb982e3616e70128994fdecf2368a259c8a489https://git.kernel.org/stable/c/2322b262d2205720518785c2706a3283725ba402https://git.kernel.org/stable/c/418a8f3140e07f33bbd5a81625d0ef46c0732cefhttps://git.kernel.org/stable/c/45b7461d914c867ef21c74798da8c42d13d3a0dfhttps://git.kernel.org/stable/c/48765ca7c6b71bf73a4cc8475a4bad9e2633cf61https://git.kernel.org/stable/c/59c6addfaaaa09ff7654e4d8793cb16fd22a46d4https://git.kernel.org/stable/c/9df630dafa1a59946d1da6f070d4cb64f14ea57chttps://git.kernel.org/stable/c/c766c90faf93897b77c9c5daa603cffab85ba907
2025-12-24
Published